Repro: new window.WebGLUnsignedIntArray().length; Id: WebCore::WebGLArrayInternal::lengthAttrGetter ReadAV@NULL (b1a3e1a3e9d01f17fd493d68eeb2742f) Description: Attempt to read from NULL pointer in WebCore::WebGLArrayInternal::lengthAttrGetter
This crash occurs in both Safari and Chrome -- i.e., in both the JSC and V8 bindings.
Created attachment 60136 [details] Patch From the ChangeLog: Changed custom ArrayBufferView constructors to create a fully-initialized, zero-length array when called with zero arguments. This is the simplest fix which works identically in both the JSC and V8 bindings.
Comment on attachment 60136 [details] Patch r=me
Committed r62194: <http://trac.webkit.org/changeset/62194>